Spontaneous virtual private network between portable device and enterprise network
Summary by NHIP
Spontaneous VPN Tunnel Method
The method establishes a virtual private network tunnel between a data center and an enterprise network by transmitting reply data to keep the tunnel open without placing a node at the firewall. A user access request sent to the data center is transmitted through this pre-existing tunnel to the enterprise network for data retrieval.
Claim Score by NHIP
Abstract
An enterprise network opens a virtual private network tunnel with a data center by sending the data center a data request that includes a uniform resource identifier. The data center responds by sending the enterprise network ongoing reply data. A user wishing to access network data of the enterprise network transmits an access request to the data center. The data center authenticates the identity of the user and transmits the access request to the enterprise network. The enterprise network responds to the access request by performing acts upon the network data and/or by returning network data to the data center such that the user is enabled access to the network data. In an alternative embodiment, the data center caches a copy of network data to be retrieved by a remote user when the same network data is disconnected from the enterprise network.

Term
Term ended
Expired 30 December 2022, 3.7 years ago.
- Priority
- Filed
- Granted
- Expired
- Today
45 claims: 6 independent, 39 dependent
- 1In a data center capable of communicating with a remote enterprise network, a method for enabling a user to access network data of the remote enterprise network through a data tunnel between the data center and the remote enterprise network that operates as a virtual private network, the method comprising the acts of:in response to receiving a data request from the remote enterprise network, establishing the data tunnel with the remote enterprise network, by transmitting reply data to the remote enterprise network, the data tunnel operating as a virtual private network a firewall of the remote enterprise network without requiring a virtual private network node to be placed at the firewall;continuing to transmit the reply data to the remote enterprise network in an ongoing manner such that the data tunnel is kept open;receiving an access request from a user for network data from the remote enterprise network;transmitting the access request to the remote enterprise network using the existing data tunnel that has been established and exists prior to the data center having received the access request;receiving the network data from the remote enterprise network in response to the access request;and transmitting the network data to the user.
- 13In an enterprise network capable of communicating with a remote data center network, a method for enabling a user to access network data of the enterprise network through a data tunnel between the remote data center and the enterprise network that operates as a virtual private network, the method comprising the acts of transmitting a data request to the remote data center;receiving reply data that has been transmitted by the remote data center in response to the data request and that establishes the data tunnel with the remote data center, the data tunnel operating as a virtual private network through a firewall or the enterprise network without requiring a virtual private network node to be placed at the firewall;receiving the reply data from the remote data center in an ongoing manner such that the data tunnel is kept open;receiving, from the remote data center, an access request to access network data of the enterprise network, the access request having been received by the remote data center from the user and thereafter transmitted by the remote data center to the enterprise network through the data tunnel that has been established and exists prior to the remote data center having received the access request;and in response to the access request, transmitting the network data to the remote data center such that the user is enabled to access the network data.
- 23In a data center capable of communicating with a remote enterprise network, a method for enabling a user to access network data of the remote enterprise network through a data tunnel between the data center and the remote enterprise network that operates as a virtual private network, the method comprising the acts of:receiving, from the remote enterprise network, a uniform resource identifier associated with a resource of a server of the data center;in response to receiving the uniform resource identifier, invoking the resource to establish the data tunnel with the remote enterprise network by transmitting reply data, and continuing to transmit the reply data to the remote enterprise network in an ongoing manner, such that the data tunnel is kept open between the data center and the remote enterprise network, the data tunnel operating as a virtual private network through a firewall of the remote enterprise network without requiring a virtual private network node to be placed at the firewall;receiving an access request to access network data of the remote enterprise network from the user;inserting the access request into the reply data and transmitting the access request to the remote enterprise network using the data tunnel that has established and exists prior to the data center having received the access request;receiving the network data from the remote enterprise network in response to the access request;and transmitting the network data to the user.
- 28A computer program product for implementing in a data center a method for enabling a user to access network data of a remote enterprise network through a data tunnel between the data center and the remote enterprise network that operates as a virtual private network, the computer program product comprising:a computer-readable medium carrying computer-executable instructions for implementing the method, the computer-executable instructions comprising: program code means for establishing the data tunnel with the remote enterprise network by transmitting reply data to the remote enterprise network in response to receiving a data request from the remote enterprise network, the data tunnel operating as a virtual private network through a firewall of the remote enterprise network without requiring a virtual private network node to be placed at the firewall;program code means for continuing to transmit the reply data to the remote enterprise network in an ongoing manner such that the data tunnel is kept open;program code means for receiving an access request from a user for network data from the remote enterprise network;program code means for transmitting the access request to the remote enterprise network using the data tunnel that has been established and exists prior to the data center having received the access request;program code means for receiving the network data form the remote enterprise network in response to the access request;and program code means the transmitting the network data to the user.
- 34Broadest claimClaim Score 48, average(NHIP)In an enterprise network capable of communicating with a remote data center, a method for enabling a user to manipulate network data of the enterprise network through a data tunnel between the remote data center and the enterprise network that operates as a virtual private network, the method comprising the acts of transmitting a data request to the remote data center;receiving reply data that has been transmitted by the remote data center in response to the data request and that establishes the data tunnel with the remote data center, the data tunnel operating as a virtual private network through a firewall of the enterprise network without requiring a virtual private network node to be placed at the firewall;receiving the reply data from the remote data center in an ongoing manner such that the data tunnel is kept open;receiving, from the remote data center, a user request for an act to be performed on network data of the enterprise network, the user request having been received by the remote data center from the user and thereafter transmitted by the remote data center to the enterprise network through the data tunnel that has been established and exists prior to the data center having received the user request;and upon receiving the user request, performing the act on network data of the enterprise network.
- 39In a data center capable of communicating with a remote enterprise network, a method for enabling a user to access network data of the remote enterprise network through a data tunnel between tho data center and the remote enterprise network that operates as a virtual private network, the method comprising:establishing the data tunnel with the remote enterprise network by transmitting reply data to the remote enterprise network in response to receiving a data request from the remote enterprise network;continuing to transmit the reply data to the remote enterprise network in an ongoing manner to keep the data tunnel open;receiving network data from the remote enterprise network through the data tunnel, the data tunnel operating as a virtual private network through a firewall of the enterprise network without requiring a virtual private network node to be placed at the firewall;caching a copy of the network data in a database of the data center, receiving an access request to access network data of the remote enterprise network from the user;retrieving the network data from the database in response to the access request;and transmitting the network data to the user.
Independent claims6
75 paragraphs in 5 sections, as filed
RELATED APPLICATION
0001This application claims the benefit of U.S. Provisional Patent Application Ser. No. 60/257,481, entitled “SECURE ACCESS SESSION WITHOUT MODIFYING EXISTING FIREWALL,” and filed Dec. 20, 2000, which is incorporated herein by reference.
BACKGROUND OF THE INVENTION
00021. The Field of the Invention
0003The present invention relates to methods and systems for enabling a user to access data over a virtual private network. More particularly, the present invention relates to methods and systems for providing a user with controlled mobile remote access to network data over a spontaneous virtual private network.
00042. Background and Related Art
0005In today's business world, many businesses protect their data from unauthorized access by installing firewalls into their network infrastructure. Typically, a firewall is configured to prevent unidentified users from accessing network data from a remote location. Although firewalls are generally very beneficial for enabling a business to have more control over who accesses its network data, they also have the undesirable consequence of disconnecting mobile professionals from critical and urgent business information when they are away from the office or otherwise unable to gain local access to the network data.
0006To enable a mobile professional to access business information from a remote location, some businesses have installed virtual private networks (VPNs) between the business and designated remote locations, such as from a professional's home or satellite office. The function of a VPN is to open a secure connection between the business network and a designated remote location through the business firewall. Although beneficial for providing remote access to network data, a VPN requires the installation of expensive hardware and/or software at the business network and sometimes at the remote location.
0007An embodiment of a prior art system and method for enabling remote access to network data over a VPN is shown in <figref idref="DRAWINGS">FIG. 1</figref>. As shown, a user <b>10</b> communicates with the business network <b>12</b> from a remote location through a VPN tunnel <b>14</b>. At each end of the VPN tunnel <b>14</b> is a VPN node <b>16</b>, <b>18</b>. At the business network <b>12</b>, the VPN node <b>16</b> straddles the business network's firewall <b>20</b>. Network data <b>22</b> is transmitted through the firewall <b>20</b> at the VPN node <b>16</b> and through the VPN tunnel <b>14</b> to the user <b>10</b>. According to the prior art, it is also possible for a remote business <b>23</b> to communicate with the business network <b>12</b> through a VPN tunnel <b>24</b>, as shown between VPN node <b>16</b> and VPN node <b>26</b>.
0008VPN hardware and software employ encryption technology and other security features at the VPN nodes to ensure that data transmitted through a VPN tunnel is not intercepted and that the user or remote business is authorized to access the business network data. The benefits of a VPN, however, are limited to discrete remote locations where the appropriate VPN software and/or hardware is installed. Accordingly, VPNs do not currently provide users with mobile remote access to network data stored behind business firewalls. In particular, a prior art VPN does not enable a user to access network data from a telephone while commuting in a moving vehicle.
0009There are also consequences associated with establishing a prior art VPN. In particular, a VPN requires a port or hole to be opened in the business firewall so that data can be transmitted between the business network and the remote VPN node. It is over the VPN port that hardware or software must be installed to ensure that only authorized users are provided access to the network data. However, despite the security mechanisms of the VPN to authenticate the identity of the user, the potential for a hacker to obtain unauthorized access to the business network is increased. For instance, a hacker may attack the firewall at the business VPN node or may obtain unauthorized access to network data by hacking into a remote user's computing device at the remote VPN node location. To prevent hackers from gaining access to network data, many businesses install secondary firewalls, so that if a hacker comes through the first firewall, they are more likely to be stopped before they penetrate the secondary firewall.
0010<figref idref="DRAWINGS">FIG. 1</figref> illustrates a typical firewall configuration for preventing unauthorized access to network data. This firewall configuration includes a primary firewall <b>20</b>, a secondary firewall <b>28</b>, and a demilitarized zone (DMZ) <b>30</b>, which is the area between the primary firewall <b>20</b> and the secondary firewall <b>28</b>.
0011Many businesses install proxy servers to intercept and filter data transmitted through the business's firewall infrastructure. Proxy servers are also beneficial for many other reasons, one of which is to enable users to access the Internet from behind a business firewall while enabling a business to limit the Internet sites that can be accessed. Proxy servers also hide the true identity of the Internet user by acting as a proxy in transmitting user requests. By acting as a proxy in transmitting user requests, the proxy server is able to filter user requests so that only qualified requests are honored. In essence, a proxy server can enhance the protection of a firewall infrastructure by prohibiting unauthorized requests from being honored. Proxy servers are particularly important for businesses that permit employees to access the Internet because Internet access requires additional holes or ports to be opened in the firewall infrastructure. Typically these ports include “port <b>80</b>” and “port <b>443</b>.” A firewall and proxy server can collectively operate to prevent unauthorized users on the Internet from obtaining control over the business network by ensuring that data transmitted through the ports complies with defined protocols. Even though Internet access initiated from within a business typically requires “port <b>80</b>” and “port <b>443</b>” to be opened in the firewall, the potential for a hacker to gain unauthorized remote access to a business network through “port <b>80</b>” and “port <b>443</b>” can be substantially limited by using appropriate firewall and proxy server configurations.
0012The hole created in the firewall by a VPN, however, is difficult to police even with effective VPN hardware and software. A VPN also increases the number of fronts that have to be monitored, including the newly opened VPN port in the business firewall and each of the remote VPN nodes. Accordingly, although VPNs are beneficial for enabling authorized users to access network data from remote locations, VPNs are likewise detrimental for facilitating unauthorized access to network data from remote locations. VPNs make it difficult to police business firewalls, make it difficult to use proxy servers, and in consequence, weaken firewalls and provide users, authorized or not, with too much control over network data. VPNs can also be very expensive to install and maintain. Nevertheless, because of today's business need for mobile professionals to have access to critical and urgent information away from the office, many businesses are willing to expend the resources and take the risks that are associated with establishing VPNs.
0013In view of the foregoing, there is currently a need in the art for providing mobile professionals with controlled access to network data that is stored behind business firewalls, without weakening the associated firewall infrastructure and in an economic manner. There is also a need for providing users with mobile remote access to network data through a VPN, such that network data does not have to be obtained from discrete, predefined, remote VPN node locations. For example, it would be an advancement in the art to enable a mobile professional to access email messages through a VPN, while the mobile professional is commuting in a moving vehicle from a portable telephone device.
SUMMARY OF THE INVENTION
0014The present invention relates to methods and systems for providing users with controlled mobile remote access to business network data through a virtual private network (VPN), without requiring the installation of expensive software or hardware at the business firewall, and without opening additional ports or holes in the business's firewall that would weaken the firewall infrastructure, but rather by establishing a secure data tunnel through a pre-opened Internet port.
0015The present invention enables a mobile professional to remotely access critical and urgent business information such as email, from behind a business firewall, while on the move, without requiring remote access to be obtained from predefined, discrete VPN node locations that must be configured with expensive VPN software and hardware.
0016A remote user is enabled to access network data from a business or enterprise location by communicating with a data center that has an established data tunnel with the enterprise network. The data tunnel is established when the enterprise network transmits an initial data request to the data center and the data center replies with an ongoing transmission of reply data. The enterprise network transmits the initial data request and receives the reply data through a pre-opened network port, such as through Internet “port <b>80</b>” or “port <b>443</b>.” The data center uses a web server to communicate with the enterprise network and the enterprise network uses a spontaneous virtual private network (SVPN) module to communicate with the data center.
0017In one embodiment, the SVPN module initiates a data request from within the enterprise network and monitors the resulting communication channel to ensure that it remains open. If the channel is closed for any reason, the SVPN module reinitiates the data request and opens a new channel. The data request includes a uniform resource identifier (URI), or a request to access resources associated with a web server of the data center. In response to this request, the web server of the data center transmits reply data associated with the URL back to the enterprise network in an ongoing manner so that the communication channel between the data center and the enterprise network remains open. In effect, the data center never completes the transmission of the reply data to the enterprise network. The web server also updates a database of the data center of the status of any open communication channels. The database is particularly useful when the data center includes multiple web servers, only one of which has an open communication channel with the enterprise network.
0018The channel of communication between the data center and the enterprise network is a data tunnel that operates as a VPN tunnel. Using Transmission Control Protocol/Internet Protocol (TCP/IP), HyperText Transfer Protocol with Secure Sockets Layer Protocol (HTTPS), and IP Security Protocol (IPsec), data is encrypted in packets and transmitted through the data tunnel using “port <b>443</b>” of the enterprise network. In another embodiment, the data tunnel is established through “port <b>80</b>” and the data is encrypted using TCP/IP, IPsec, and HyperText Transfer Protocol (HTTP) without using Secure Sockets Layer Protocol (SSL). In one embodiment, a proxy server screens data transmitted through the ports to ensure compliance with the defined protocols.
0019A remote user wishing to access network data from the enterprise network opens a line of communication with the data center using a communication device such as a telephone device or a computer device that is connected to the Internet. The user then generates a request to access network data and transmits the request to the data center. If a telephone device is used, then the data center receives the access request at a telephony node and the telephony node transmits the access request to one of the web servers included in the data center. If the web server has an established data tunnel with the enterprise network, then the access request is transmitted from the web server to the SVPN module of the enterprise network through the data tunnel. If, however, there is not an open data tunnel between the web server and the enterprise network then the web server checks the database to see if there is another server of the data center that is transmitting reply data to the enterprise network through an established data tunnel. If there is another web sever maintaining an open data tunnel with the enterprise network, then the telephony node is notified and the access request is redirected to the other web server and subsequently transmitted from the other web server to the SVPN module of the enterprise network.
0020The enterprise network processes the access request that is received at the SVPN module by performing any act on the network data that the SVPN module is configured to allow. In one embodiment, processing the access request includes retrieving email data or web page data and transmitting the data back to the user. The SVPN module is configured in another embodiment to allow predefined functions to be performed on the network data, while preserving a business's control over what data a remote user can access and manipulate. The predefined functions include, but are not limited to deleting email messages and faxing email messages to the user.
0021The SVPN module establishes a second data tunnel with the data center by transmitting to the data center any requested data. The second data tunnel is a temporary data tunnel and is established between the enterprise network and the same web server that is in communication with the enterprise network over the first data tunnel. The second data tunnel is closed and the remote user is provided access to the network data as soon as the network data is received by the data center. If a telephone device is used by the user to communicate with the data center, then the requested network data is transmitted from the web server through the telephony node of the data center to the user's telephone device in an intelligible format, such as a digital display format or an audio format. For example, when the network data comprises an email message, the text of the email can be displayed on the liquid crystal display (LCD) of the user's telephone device or read to the user over the telephone device. Alternatively, a user can access network data directly over the Internet by opening an Internet communication link directly with the web server of the data center.
0022In one embodiment, the data center authenticates the identity of the user before the user is enabled access to the requested network data. This is accomplished by requiring the user to enter a secret personal identification number.
0023In view of the forgoing, it should be appreciated that the present invention is an improvement over the prior art. In particular, the present invention enables a user to have mobile remote access to network data over a secure data tunnel while preserving a business's ability to limit how much access to network data is permitted through the data tunnel.
0024Additional features and advantages of the invention will be set forth in the description which follows, and in part will be obvious from the description, or may be learned by the practice of the invention. The features and advantages of the invention may be realized and obtained by means of the instruments and combinations particularly pointed out in the appended claims. These and other features of the present invention will become more fully apparent from the following description and appended claims, or may be learned by the practice of the invention as set forth hereinafter.
BRIEF DESCRIPTION OF THE DRAWINGS
In order to describe the manner in which the above-recited and other advantages and features of the invention can be obtained, a more particular description of the invention briefly described above will be rendered by reference to specific embodiments thereof which are illustrated in the appended drawings. Understanding that these drawings depict only typical embodiments of the invention and are not therefore to be considered to be limiting of its scope, the invention will be described and explained with additional specificity and detail through the use of the accompanying drawings in which:
<figref idref="DRAWINGS">FIG. 1</figref> illustrates a prior art system for enabling a user and a remote enterprise network to access a business's data through virtual private network tunnels.
<figref idref="DRAWINGS">FIG. 2</figref> illustrates, in exemplary system that provides a suitable operating environment for the present invention, an enterprise network in communication with a web server of a data center and a user in communication with a telephony node of the data center.
<figref idref="DRAWINGS">FIG. 3</figref> illustrates a method for establishing a data tunnel between an enterprise network and a data center which includes transmitting a data request from the enterprise network to the data center, and the enterprise network receiving reply data from the data center.
<figref idref="DRAWINGS">FIG. 4</figref> illustrates a method for transmitting network data from an enterprise network to a data center to enable a user access to the network data, wherein network data is transmitted through a data tunnel between the enterprise network and a data center.
<figref idref="DRAWINGS">FIG. 5</figref> illustrates a flow diagram of one embodiment of the method of the present invention for enabling a user to access network data from an enterprise network.
DETAILED DESCRIPTION OF THE INVENTION
0031The present invention extends to both methods and systems for enabling user access to network data of an enterprise network through a spontaneous virtual private network from a mobile remote location using a portable device.
0032A user generates an access request for network data, such as email, using a telephone or computer device, and transmits the access request to a data center. The data center authenticates the identity of the user and transmits the access request to the appropriate enterprise network through an established data tunnel that operates as a virtual private network (VPN). The data tunnel is opened in response to a data request that is transmitted from the enterprise network to the data center. Upon receiving the access request, the enterprise network retrieves network data and transmits the network data through a second data tunnel to the data center where it is subsequently transmitted to the user.
0033Embodiments of the present invention include or are incorporated in computer-readable media having computer-executable instructions or data structures stored thereon. Examples of computer-readable media include RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, or any other medium which can be used to carry or store desired program code means in the form of computer-executable instructions or data structures and which can be accessed by a general purpose or special purpose computer. When information is transferred or provided over a network, tunnel, channel or another communications connection (either hardwired, wireless, or a combination of hardwired or wireless) to a computer, the computer properly views the connection as a computer-readable medium. Thus, any such connection is properly termed a computer-readable medium. Combinations of the above should also be included within the scope of computer-readable media. Computer-executable instructions comprise, for example, instructions and data which cause a general purpose computer, special purpose computer, or special purpose processing device to perform a certain function or group of functions. The computer-executable instructions and associated data structures or modules represent an example of program code means for executing the steps of the invention disclosed herein.
0034The invention further extends to computer systems for enabling a remote user access to network data of an enterprise network that is stored behind enterprise network firewalls. This includes, but is not limited to, opening data tunnels that operate as virtual private networks between the enterprise network and a data center, and transmitting network data through the data tunnels. Those skilled in the art will understand that the invention may be practiced in many environments with many types of computer and telephone systems, including portable computers, telephones, wireless telephones, PDA's, personal computers, multi-processor systems, network PCs, minicomputers, mainframe computers and the like.
00351. System Environment
0036<figref idref="DRAWINGS">FIG. 2</figref> illustrates an embodiment of the systems and methods of the present invention for enabling a user <b>10</b> to access network data <b>22</b> of an enterprise network <b>40</b> through a data tunnel <b>42</b> that operates as a virtual private network (VPN) between a data center <b>44</b> and the enterprise network <b>40</b>. In one embodiment, enterprise network <b>40</b> is a computer network of a business that contains network data <b>22</b> protected behind firewalls <b>20</b> and <b>28</b> from unauthorized access.
0037As used herein, the term “enterprise network” should be broadly construed to include any computing environment where tasks are performed by processing devices that are linked together. The enterprise network <b>40</b> may include, for example, the computing environment of any business, corporation, individual, or other entity. In the enterprise network <b>40</b>, computer-executable instructions and program modules for performing the features of the invention may be located in local and remote memory storage devices.
0038The terms “network data” and “business network data” should be construed to include any data that is stored in local and remote memory storage devices and is accessible to the enterprise network <b>40</b>. Network data <b>22</b> may include for example, email data or web page data. In one embodiment, network data <b>22</b> is protected behind a firewall infrastructure that includes firewalls <b>20</b> and <b>28</b>. It should be appreciated, however, that network data <b>22</b> may include any data that is accessible to the enterprise network <b>40</b>, even if it is not protected behind the firewall infrastructure
0039The term “tunnel” should be interpreted to include any channel or other line of communication through which data can be securely transmitted. One skilled in the art will appreciate that there are numerous protocols and methods of encryption and authentication that can be employed to enable secure communication through a tunnel, such that the data transmitted through the tunnel is delivered only to an identified user who is authorized to access said data. It should further be appreciated that the terms “tunnel,” “data tunnel,” and “channel,” are interchangeable, as used herein. The tunnel operates as a virtual private network by enabling secure remote access to network data through a business's firewall infrastructure.
0040According to the present invention, as shown in <figref idref="DRAWINGS">FIG. 3</figref>, a data tunnel <b>42</b> is established between the enterprise network <b>40</b> and the data center <b>44</b>. The data tunnel <b>42</b> is opened when the enterprise network <b>40</b> transmits a data request <b>50</b> to the data center <b>44</b> and the data center <b>44</b> replies with an ongoing transmission of reply data <b>53</b>. As used herein, the term “data request” should be broadly construed to include a request for data from the data center and may include a uniform resource identifier (URI), which represents request for the data center to provide access to a web page, HyperText Markup Language HTML) data, Extensible Markup Language (XML) data, or other data resources of web server <b>60</b>.
0041As shown, data request <b>50</b> and reply data <b>53</b> are transmitted through firewalls <b>20</b> and <b>28</b> of the enterprise network <b>40</b>. One skilled in the art will appreciate that firewalls <b>20</b> and <b>28</b> can include hardware, software, or a combination of both. Essentially, a firewall is a security mechanism that prohibits access through designated ports of a network and ensures network data cannot be accessed from an unauthorized user from outside of the firewall.
0042Also shown in <figref idref="DRAWINGS">FIG. 3</figref>, the data center <b>44</b> receives the data request <b>50</b> at a server, which in this embodiment includes web server <b>60</b>. It should be appreciated that data center <b>44</b> may comprise multiple web servers <b>60</b>, <b>60</b><i>a</i>, and <b>60</b><i>b</i>, as shown in <figref idref="DRAWINGS">FIG. 2</figref>. Multiple web servers <b>60</b>, <b>60</b><i>a</i>, and <b>60</b><i>b</i>, enable the data center <b>44</b> to communicate with multiple enterprise networks and to maintain multiple data tunnels, not shown. It should be appreciated that according to the present invention, multiple data tunnels can be established between a single enterprise network and a single web server or between a single enterprise network and multiple web servers.
0043Returning now to <figref idref="DRAWINGS">FIG. 3</figref>, the enterprise network <b>40</b> uses a spontaneous virtual private network (SVPN) module <b>52</b> to actually transmit the data request <b>50</b> to the data center <b>44</b> and to receive the reply data <b>53</b> in response. Reply data <b>53</b> should be construed to include any data transmitted by the data center in response to receiving the data request <b>50</b> and which is transmitted in an ongoing manner so as to keep open the tunnel <b>42</b> between the data center <b>44</b> and the enterprise network <b>40</b>. In one embodiment, this is accomplished when the enterprise network <b>40</b> requests that the web server <b>60</b> open a web page, which can be any type of data resource, such as an HTML document or XML document, provided by the web server <b>60</b>. In response, web server <b>60</b> initiates the transmission of the web page and transmits it in an ongoing manner at a rate such that the transmission of the data has an indefinitely long duration. This keeps the tunnel <b>42</b> open by continually transmitting reply data <b>53</b> to the enterprise network <b>40</b>.
0044The SVPN module <b>52</b> monitors the tunnel <b>42</b> to ensure that the tunnel <b>42</b> remains open. If for any reason the tunnel <b>42</b> is closed, the SVPN module opens a new data tunnel with the data center <b>44</b> by transmitting a new data request to the data center <b>44</b>. Although several acts are described herein as being specifically performed by the SVPN module <b>52</b>, it should be appreciated that inasmuch as the enterprise network <b>40</b> comprises the SVPN module <b>52</b>, any acts performed by the SVPN module <b>52</b> are also acts performed by the enterprise network <b>40</b>.
0045Returning now to <figref idref="DRAWINGS">FIG. 2</figref>, the data center <b>44</b> includes a database <b>62</b>. Database <b>62</b> keeps track of any data tunnel <b>42</b> that is maintained by web server <b>60</b>. Web server <b>60</b> communicates with database <b>62</b> and notifies the database <b>62</b> of the status of the data tunnel <b>42</b>. This enables the data center <b>44</b> to transmit a user's request for network data <b>22</b> to the appropriate web server <b>60</b>. A user request for network data <b>22</b> is referred to herein as access request <b>70</b>. Access request <b>70</b> is received by the data center <b>44</b> through a line of communication <b>84</b> that is initiated by the user <b>10</b>.
0046In one embodiment, the user <b>10</b> generates the access request <b>70</b> and transmits the access request <b>70</b> to the data center <b>44</b> using a telephone device. According to this embodiment, telephony nodes <b>80</b> of the data center <b>44</b> receive the access request <b>70</b> from the user <b>10</b>. Upon receiving an access request <b>70</b>, the telephony nodes <b>80</b> communicate with web server <b>60</b>. If web server <b>60</b> has a data tunnel <b>42</b> established with an appropriate enterprise network <b>40</b> from which network data <b>22</b> is requested, then the access request <b>70</b> is transmitted to the web server <b>60</b>. However, if the web server <b>60</b> does not have a tunnel <b>42</b> established with the appropriate enterprise network <b>40</b>, then the web server <b>60</b> communicates with the database <b>62</b> to determine which web server, if any, does have a tunnel <b>42</b> established with the appropriate enterprise network <b>40</b>, in which case the access request <b>70</b> is redirected to the appropriate web server.
0047In an alternative embodiment, the telephony nodes <b>80</b> communicate directly with the database <b>62</b> to ascertain which web server has an established tunnel with the appropriate enterprise network <b>40</b> from which the access request <b>70</b> requires network data <b>22</b> to be accessed. In yet another embodiment, a user initiates a line of communication <b>84</b> directly with the web server <b>60</b>. This is accomplished, for example, when the user accesses the web server <b>60</b> over the Internet, or when a web page of the web server <b>60</b> is opened by the user over the Internet by means of a personal computer or another device that can provide graphical access to data.
0048The data tunnel <b>42</b> between the data center <b>44</b> and the enterprise network <b>40</b> uses Transmission Control Protocol/Internet Protocol (TCP/IP), HyperText Transfer Protocol with Secure Sockets Layer Protocol (HTTPS), and IP Security Protocol (IPsec). Using these protocols, data requests, network data, reply data and access requests are encrypted in packets and transmitted through the data tunnel <b>42</b> using “port <b>443</b>”, not shown, of the enterprise network. “Port <b>443</b>” is already open to enable users to access the Internet from the enterprise network <b>40</b>, within the firewalls <b>20</b> and <b>28</b>.
0049In another embodiment the data tunnel <b>42</b> is established through “port <b>80</b>” of the enterprise network, such that the data requests, network data, reply data and access requests are is encrypted using TCP/IP, IPsec, and HyperText Transfer Protocol (HTTP) without using Secure Sockets Layer Protocol (SSL). It should be appreciated that the present invention may utilized any Internet tunneling protocol, including Layer Two Forwarding (L2F), and Layer Two Tunneling Protocol (L2TP). Port “<b>80</b>” is also already open to enable Internet access from within the firewall infrastructure of the enterprise network <b>40</b>. According to this embodiment, proxy server <b>82</b>, as shown in <figref idref="DRAWINGS">FIGS. 3–4</figref>, filters through the data packets to verify that they comply with the defined protocols If a data request <b>50</b>, network data <b>22</b>, reply data <b>53</b>, or access request <b>10</b> is not properly packetized then the proxy server <b>82</b> will not permit it to pass through the data tunnel <b>42</b>. In this manner, the proxy server <b>82</b> enhances the protection of the firewall infrastructure by ensuring that only authorized data transmissions and requests are transmitted into or out of the enterprise network <b>40</b> through the data tunnel <b>42</b>.
0050As described, the present invention uses preexisting open ports in the firewall infrastructure to enable secure VPN type communication from remote mobile locations. Accordingly, it should also be appreciated that the present invention is an improvement over the prior art because additional ports are not required to be opened in the firewall infrastructure, which would require the installation of sophisticated and expensive VPN hardware and software. Furthermore, the present invention enables a proxy server to filter any data packets transmitted through the ports to ensure compliance with the defined protocols.
0051The system and environment just described is a suitable environment and system for practicing the method of the present invention for enabling a user access to network data of an enterprise network through a virtual private network from a remote location using a portable device.
00522. User Access to Network Data
0053One embodiment of the method of the present invention for enabling a user access to network data from a remote location is illustrated in <figref idref="DRAWINGS">FIGS. 4 and 5</figref>. Turning now to <figref idref="DRAWINGS">FIG. 4</figref>, a user <b>10</b> wishing to access network data <b>22</b> of the enterprise network <b>40</b> from a remote location opens a line of communication <b>84</b> with the data center <b>44</b> using a communication device such as a telephony device or a computing device that is connected to the Internet. The data center <b>44</b> authenticates the identity of the user <b>10</b> to verify that the user <b>10</b> has authority to access network data <b>22</b> of the enterprise network <b>40</b>. In one embodiment, the user's identity is authenticated when the user, using a telephony device or Internet computing device, enters a personal identification number. In another embodiment the user's identity is confirmed over the Internet using encryption technology, such as twin-key encryption, with corresponding public and private keys assigned to the user <b>10</b>. One skilled in the art will recognize there are various methods for authenticating the identity of a user, any of which may be used in accordance with the present invention. Other such methods for authenticating the identity of a user include, but are not limited to, tokens and smart cards.
0054Once the identity of the user <b>10</b> is authenticated, the user transmits an access request to the data center <b>44</b> where it is received by the web server <b>60</b>. Access request <b>70</b> may include any request requiring access to network data <b>22</b>. For example, access request <b>70</b> may include a request to receive access to email messages, web pages or other data of the enterprise network that is protected behind a firewall infrastructure or accessible to the enterprise network. In one embodiment, the user <b>10</b> uses a computer device to open a line of communication <b>84</b> with the web server <b>60</b> over the Internet. In this embodiment, the access request <b>70</b> is received directly by the web server <b>60</b>. In another embodiment, a user <b>10</b> uses a telephone device to transmit the access request <b>70</b> to the data center <b>44</b>. According to this alternative embodiment, the access request is received indirectly by the web server <b>60</b> through telephony nodes <b>80</b>, as described above in reference to <figref idref="DRAWINGS">FIG. 2</figref>.
0055Upon receiving the access request <b>70</b>, the web server <b>60</b> transmits the access request <b>70</b> to the enterprise network <b>40</b> through the established data tunnel <b>42</b> that was opened at the initial request of the enterprise network <b>40</b>, as described above with reference to <figref idref="DRAWINGS">FIGS. 2 and 3</figref>. The access request <b>70</b> is packetized with the reply data <b>53</b>.
0056Access request <b>70</b> is received by the enterprise network <b>40</b> at the SVPN module <b>52</b>. The enterprise network <b>40</b> processes the access request <b>70</b> by performing any act on the network data <b>22</b> that is requested by the access request <b>70</b>. In one embodiment, the acts that can be performed on network data are limited to predefined acts according to the configuration of the SVPN module <b>52</b>. The predefined acts can include any acts that an enterprise network wishes to enable the SVPN module <b>52</b> to allow. By allowing the SVPN module <b>52</b> to control what acts are performed on the network data <b>22</b>, the enterprise network <b>40</b> is able to maintain control over access to network data <b>22</b> and can control how network data <b>22</b> is manipulated within in the enterprise network <b>40</b>. Predefined acts may include, but are not limited to, retrieving email headers, retrieving email message bodies, retrieving web page data, deleting email, faxing email data or web page data to the user, transmitting network data <b>22</b> to the data center <b>44</b>. The SVPN module <b>52</b> obtains network data from the enterprise network using an appropriate means, which may include, but is not limited to, Post Office Protocol (POP) or Simple Mail Transfer Protocol (SMTP).
0057The SVPN module <b>52</b> transmits network data <b>22</b> back to the data center <b>44</b> over a second data tunnel <b>90</b>. The second data tunnel <b>90</b> operates as a temporary virtual private network between the enterprise network <b>40</b> and data center <b>44</b>. Data tunnel <b>90</b> is established through the same port, Internet “port <b>443</b>,” that is used for data tunnel <b>42</b>, and uses the same protocols discussed above to ensure security of the data transmission. In another embodiment, “port <b>80</b>” is used with corresponding protocols. Proxy server <b>82</b> ensures that desired protocols are complied with.
0058Data tunnel <b>90</b> is established with the same web server <b>60</b> that is transmitting reply data <b>53</b> to the enterprise network <b>40</b> or with another web server, not shown, of the data center <b>44</b>. Data tunnel <b>90</b> is closed and the user <b>10</b> is provided access to network data <b>22</b> as soon as it is received by the data center <b>44</b>. If a telephone device is used by the user <b>10</b> to communicate with the data center <b>44</b> then the network data <b>22</b> is transmitted from the web server <b>60</b> to the user through the telephony nodes <b>80</b>, shown in <figref idref="DRAWINGS">FIG. 2</figref>.
0059It should be appreciated that this invention can be practiced in combination with U.S. patent application Ser. No. 09/464,989, filed Dec. 16, 1999, entitled “Voice Interface for Electronic Documents,” which is incorporated herein by reference, to enable a user to receive audio access to network data. In one embodiment, network data <b>22</b> comprises an email message and the data center <b>44</b> reads the text of the email message to the user <b>10</b> over the user's telephone device, or alternatively displays the email message on the user's telephone device. In another embodiment, the user <b>10</b> accesses network data <b>22</b> directly over the Internet from a line of communication <b>84</b> that is established directly with the web server <b>60</b>.
0060A user can generate any number of access requests which will each be processed discretely. By breaking up user requests into discrete transactions, the present invention enhances security and control over network data by preventing a user, authorized or not, from gaining too much control over network data.
0061<figref idref="DRAWINGS">FIG. 5</figref> illustrates a flow diagram of one embodiment of the present invention. As shown, in step <b>100</b>, the enterprise network transmits a data request to the data center. Upon receiving the data request, step <b>102</b>, the data center transmits ongoing reply data back to the enterprise network, step <b>104</b>. In one embodiment, the reply data includes Markup Language Data, such as HTML data and XML data. In step <b>106</b>, the enterprise network receives the ongoing reply data. Steps <b>100</b>–<b>106</b> establish a data tunnel between the enterprise network and the data center. In one embodiment, the data tunnel is established through port “<b>443</b>.” In another embodiment, the data tunnel is established through port “<b>80</b>.”
0062A user accesses network data of the enterprise network by first connecting to the data center, step <b>108</b>. Next, the user generates and transmits an access request to the data center, step <b>110</b>. In one embodiment, the access request is generated by the user using a telephone device. In an alternative embodiment, the user generates the access request over the Internet using a computer. Upon receiving the access request, step <b>112</b>, the data center transmits the access request to the enterprise network, step <b>114</b>, through the data tunnel that was established in steps <b>100</b>–<b>106</b>.
0063In step <b>116</b>, the enterprise network receives the access request and subsequently, in step <b>118</b>, determines whether the access request is a valid access request. This may include verifying that the access request requires only predefined and authorized acts to be performed on the network data. It may also include the act of validating the identity of the user. As a matter of illustration, and not limitation, step <b>118</b> may result in the determination that retrieving an email message is a valid request and that running an attached executable program is not a valid request. The determination of what constitutes a valid access request can be predetermined and is controlled by the SVPN module. If the access request is not valid, the enterprise network does not process the request, but waits until a valid request is received, step <b>120</b>.
0064If the access request is valid and it requires network data to be transmitted back to the user, then the network data is retrieved, in step <b>124</b>, and subsequently transmitted to the data center, step <b>128</b>, through a temporary data tunnel that is opened between the enterprise network and the data center, shown in step <b>126</b>. In this embodiment, the temporary data tunnel opened in step <b>126</b> is different than the data tunnel established in steps <b>100</b>–<b>106</b>. It should be appreciated, however, that both tunnels can be established over the same ports of the enterprise network.
0065After the network data is transmitted to the data center, the temporary data tunnel is closed, step <b>130</b>, and the enterprise network waits for subsequent valid request to be received, step <b>120</b>. If the access request requires an act to be performed, such as deleting email, faxing email messages, and forwarding email, the enterprise network performs the required task, step <b>138</b>, and waits for a subsequent valid request to be received, step <b>120</b>.
0066The data center transmits the requested network data to the user, step <b>134</b>, as soon as it is received from the enterprise network, step <b>132</b>. In one embodiment, this is accomplished by displaying the requested network data on a web page that being viewed by the user. In another embodiment, the requested network data is transmitted to a telephone device that is being used by the user, in either digital format or in audio format. The user receives the requested network data, step <b>136</b>, and either disconnects from the data center, step <b>138</b>, or transmits a subsequent access request to the data center, step <b>110</b>.
0067According to the present invention, a user can also access network data that is cached in the database of the data center. According to this embodiment, described in reference to <figref idref="DRAWINGS">FIG. 2</figref>, network data <b>22</b> is cached in database <b>62</b>, even before the user <b>10</b> generates an access request <b>70</b> for the network data <b>22</b>. This embodiment is particularly useful for enabling a user <b>10</b> to quickly access network data <b>22</b> when the network data <b>22</b> is disconnected. Network data <b>22</b> is disconnected whenever it is not easily or quickly retrievable by the enterprise network <b>40</b>. For example, if network data <b>22</b> is stored in a very large remote memory device within the enterprise network <b>40</b>, it may take several minutes for the network data <b>22</b> to be retrieved. Other network data <b>22</b> that is disconnected includes data that is stored on the desktop or local computer drive of a computer that is turned off. Yet another example of disconnected network data is any data that is stored on a portable computer or storage device that is periodically disconnected from the enterprise network <b>40</b>, such as a laptop computer or a PDA.
0068According to this embodiment, the enterprise network <b>40</b> establishes a new temporary data tunnel between the SVPN <b>52</b> and the web server <b>60</b>. The temporary data tunnel is established in similar fashion to that of data tunnel <b>90</b>, which is described in reference to <figref idref="DRAWINGS">FIG. 4</figref>. Once the temporary data tunnel is established, network data <b>22</b> is uploaded to the database <b>62</b> of the data center <b>44</b> through the temporary data tunnel. The process of uploading the network data <b>22</b> includes the act of packetizing the network data according to the established protocols that have been described above. Once the network data <b>22</b> is received, the data center <b>44</b> caches a copy of the network data <b>22</b> in the database <b>62</b>. The cached copy of network data <b>22</b> is updated whenever a newer version of the network data <b>22</b> is received by the database <b>60</b>. The frequency of which newer versions of the network data <b>22</b> are received is predetermined by the authorization and configuration of the enterprise network <b>40</b>.
0069In one example, which is given as a matter of illustration and not limitation, the enterprise network generates notices that are received by all users of the enterprise network. The notices remind the users to upload their email contacts, address lists, corporate files, and other designated network data <b>22</b> so that the updated data can be retrieved off site, away from the enterprise network <b>40</b>. According to this embodiment, the user <b>10</b> controls what network data <b>22</b> is transmitted to the data center <b>44</b> and what network data <b>22</b> is cached in the database <b>62</b> according to how the user <b>10</b> responds. The user <b>10</b> may, for example, respond by ignoring the notice. Alternatively, the user <b>10</b> may respond by initiating a command that allows the SVPN <b>52</b> module to upload the designated network data <b>22</b> to the database <b>62</b> of the data center <b>44</b>. As previously discussed, the updates to the network data are transmitted through a temporary data tunnel that is established between the SVPN <b>52</b> module and the web server <b>60</b>. Upon receiving the data packets, the web server <b>60</b> decrypts the user's network data <b>22</b> and sends it to database <b>62</b> where it is cached.
0070It should be appreciated that this embodiment enables a user to synchronize disconnected data over a temporary data tunnel that operates as a virtual private network so that it can be accessed from a remote location at a later time. This embodiment also enables a user to quickly access a copy of the network data, which is cached in the database of the data center, when network data is disconnected from the enterprise network. Network data is disconnected, for example, when it is stored on a portable and physically disconnected computer, stored on a disabled network storage drive, when the network data is difficult to retrieve because of network problems, and when the network data takes a long time to retrieve because of slow connections and processing speeds.
0071According to the present embodiment, a user <b>10</b> accesses network data <b>22</b>, such as email contacts, by calling into the data center <b>44</b> using a telephone system and by generating an access request <b>70</b> for the network data <b>22</b>. Telephony nodes <b>80</b> at the data center <b>44</b> receive the user's call and accompanying access request <b>70</b>. The telephony nodes <b>80</b> also retrieve the uploaded network data <b>22</b> from the database <b>62</b> and transmit the uploaded network data <b>22</b> back to the user <b>10</b>. According to an alternative embodiment, the user <b>10</b> accesses the data center <b>44</b> directly over the Internet, in which case the web server <b>60</b> retrieves the user's uploaded network data <b>22</b> from the database <b>62</b> and transmits it back to the user <b>10</b>.
0072The present embodiment also enables a user <b>10</b> to update network data <b>22</b> by issuing commands directly to the data center <b>44</b> over an established line of communication <b>84</b> between the user <b>10</b> and the data center <b>44</b>. As a matter of illustration, a user can issue a command to delete an email contact from the cached copy of network data stored in the database of the data center. According to this example, the data center <b>44</b> responds by deleting the email contact, which effectively updates the cached copy of the network data at the data center. Data center <b>44</b> then transmits information regarding the update to the enterprise network <b>40</b>. This is accomplished by embedding the update information within the reply data <b>53</b> that is being transmitted to the enterprise network <b>40</b> through an established data tunnel, such as data tunnel <b>42</b>. The transmission of reply data <b>53</b> is shown and described in more detail in reference to <figref idref="DRAWINGS">FIGS. 3 and 4</figref>.
0073The SVPN module receives the network data updates and updates the enterprise network data accordingly. This synchronizes the enterprise network data <b>22</b> with the cached copy of the network data that is stored in database <b>62</b> of the data center <b>44</b>. It should be appreciated that this embodiment enables a remote user to update network data that is stored at the database of the data center and to further update network data stored at the enterprise network by synchronizing the network data of the enterprise network with the updated cache copy of network data stored at the data center.
0074In view of the forgoing, it should be appreciated that the present invention is an improvement over the prior art. In particular, the present invention enables a user to have mobile remote access to network data over a secure data channel while preserving a business's ability to limit how much access to network data is permitted through the data channel. The present invention also enables a remote user to access network data that is disconnected from the enterprise network. Furthermore, the present invention enables a user to update network data from a remote location over a virtual private network data tunnel.
0075The present invention may be embodied in other specific forms without departing from its spirit or essential characteristics. The described embodiments are to be considered in all respects only as illustrative and not restrictive. The scope of the invention is, therefore, indicated by the appended claims rather than by the foregoing description. All changes which come within the meaning and range of equivalency of the claims are to be embraced within their scope.
Contents5
6 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US7568107B1 | Cited by | United States of America | Search report |
| US8291026B2 | Cited by | United States of America | Applicant |
| US8762447B2 | Cited by | United States of America | Search report |
| US8086749B2 | Cited by | United States of America | Applicant |
| US2007168352A1 | Cited by | United States of America | Pre-grant |
| US2009296718A1 | Cited by | United States of America | Pre-grant |
| US8975027B2 | Cited by | United States of America | Applicant |
| US8369343B2 | Cited by | United States of America | Applicant |
| US8078736B1 | Cited by | United States of America | Applicant |
| US2010095019A1 | Cited by | United States of America | Pre-grant |
| US8005958B2 | Cited by | United States of America | Search report |
| US10116580B2 | Cited by | United States of America | Applicant |
| US7778199B2 | Cited by | United States of America | Search report |
| US7769037B2 | Cited by | United States of America | Applicant |
| US2006101090A1 | Cited by | United States of America | Pre-grant |
| US2006187937A1 | Cited by | United States of America | Pre-grant |
| US10819672B2 | Cited by | United States of America | Applicant |
| US2005015642A1 | Cited by | United States of America | Pre-grant |
| US2010228779A1 | Cited by | United States of America | Pre-grant |
| US8059527B2 | Cited by | United States of America | Applicant |
| US7346670B2 | Cited by | United States of America | Search report |
| US8468577B1 | Cited by | United States of America | Search report |
| US2009323718A1 | Cited by | United States of America | Pre-grant |
| US2006187856A1 | Cited by | United States of America | Pre-grant |
| US8935351B2 | Cited by | United States of America | Applicant |
| US2008201440A1 | Cited by | United States of America | Pre-grant |
| US2009154466A1 | Cited by | United States of America | Pre-grant |
| US2006187855A1 | Cited by | United States of America | Pre-grant |
| US8886739B2 | Cited by | United States of America | Applicant |
| US8073966B2 | Cited by | United States of America | Applicant |
| US2009327497A1 | Cited by | United States of America | Pre-grant |
| US2003229690A1 | Cited by | United States of America | Pre-grant |
| US2007283430A1 | Cited by | United States of America | Pre-grant |
| US8281384B2 | Cited by | United States of America | Search report |
| US7610345B2 | Cited by | United States of America | Applicant |
| US8751647B1 | Cited by | United States of America | Applicant |
| US9282081B2 | Cited by | United States of America | Applicant |
| US8732451B2 | Cited by | United States of America | Applicant |
| US12074841B2 | Cited by | United States of America | Applicant |
| US2010299518A1 | Cited by | United States of America | Pre-grant |
| US11652775B2 | Cited by | United States of America | Applicant |
| US10412039B2 | Cited by | United States of America | Applicant |
| US2002023210A1 | Cites | United States of America | Search report |
| US6032227A | Cites | United States of America | Search report |
| US6061796A | Cites | United States of America | Search report |
| US6081900A | Cites | United States of America | Applicant |
| US6092113A | Cites | United States of America | Applicant |
| US6092200A | Cites | United States of America | Applicant |
| US6138049A | Cites | United States of America | Search report |
| US6178505B1 | Cites | United States of America | Applicant |
| US6226748B1 | Cites | United States of America | Applicant |
| US6229809B1 | Cites | United States of America | Applicant |
| US6233608B1 | Cites | United States of America | Search report |
| US6292905B1 | Cites | United States of America | Search report |
| US6295551B1 | Cites | United States of America | Search report |
| US6411986B1 | Cites | United States of America | Search report |
| US6529500B1 | Cites | United States of America | Search report |
| US6546425B1 | Cites | United States of America | Search report |
| US6563800B1 | Cites | United States of America | Search report |
| US6609148B1 | Cites | United States of America | Search report |
| US6631416B2 | Cites | United States of America | Search report |
| US6765881B1 | Cites | United States of America | Search report |
| US6801509B1 | Cites | United States of America | Search report |
| US6874030B1 | Cites | United States of America | Search report |
| Aqun et al. “<i>Research on Tunneling Techniques in Virtual Private Networks</i>”, IEEE, Aug. 2000, pp. 691-697, especially pp. 692-696. | Non-patent | – | Third party observation |
| Aqun et al. "Research on Tunneling Techniques in Virtual Private Networks", IEEE, Aug. 2000, pp. 691-697, especially pp. 692-696. | Non-patent | – | Applicant |
| S.Cobbs, Security Issues in Internet Commerce, June 1996, pgs. 186-191 | Non-patent | – | Applicant |
20 members in 6 offices; this record represents the family
Priority claims6
| Document | Office | Kind | Date |
|---|---|---|---|
| 25748100 | United States of America | P | |
| 25748100 | United States of America | P | |
| 76746501 | United States of America | A | |
| 60257481 | – | – | – |
| US20000257481P | – | – | – |
| US20010767465 | – | – | – |
Members20
| Document | Office | Kind | |
|---|---|---|---|
| CA2430266A1 | Canada | A1 | |
| WO0250695A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU3100102A | Australia | A | |
| US2002099826A1 | United States of America | A1 | |
| EP1350171A1 | European Patent Office (EPO) | A1 | |
| WO2004079581A1 | World Intellectual Property Organization (WIPO) | A1 | |
| US2004255164A1 | United States of America | A1 | |
| JP2005501432A | Japan | A | |
| US2005055577A1 | United States of America | A1 | |
| EP1599804A1 | European Patent Office (EPO) | A1 | |
| WO2006014291A1 | World Intellectual Property Organization (WIPO) | A1 | |
| JP2006520130A | Japan | A | |
| US7124189B2This record | United States of America | B2 | |
| EP1766844A1 | European Patent Office (EPO) | A1 | |
| JP3909289B2 | Japan | B2 | |
| JP4173517B2 | Japan | B2 | |
| EP1350171A4 | European Patent Office (EPO) | A4 | |
| US7673133B2 | United States of America | B2 | |
| US8266677B2 | United States of America | B2 | |
| EP1350171B1 | European Patent Office (EPO) | B1 |
64 transactions on the USPTO file
Allowed after 2 non-final rejections, 2 final rejections, 1 RCE and 1 appeal.
- Non-final rejections
- 2
- Final rejections
- 2
- RCEs
- 1
- Appeals
- 1
Over time
Point at a mark for the transactionTransactions
| Event | Code | |
|---|---|---|
| Expire PatentEXP. | EXP. | |
| Email NotificationEML_NTR | EML_NTR | |
| Change in Power of Attorney (May Include Associate POA)PA.. | PA.. | |
| Correspondence Address ChangeC.AD | C.AD | |
| Maintenance Fee Reminder MailedREM. | REM. | |
| Entity status set to undiscounted (initial default setting or status change) | – | |
| Entity Status Set To Undiscounted (Initial Default Setting or Status Change)BIG. | BIG. | |
| Post Issue Communication - Certificate of CorrectionN423 | N423 | |
| Recordation of Patent Grant MailedPGM/ | PGM/ | |
| Patent Issue Date Used in PTA CalculationAllowedPTAC | PTAC | |
| Issue Notification MailedAllowedWPIR | WPIR | |
| Dispatch to FDCD1935 | D1935 | |
| Application Is Considered Ready for IssuePILS | PILS | |
| Issue Fee Payment VerifiedN084 | N084 | |
| Mail Notice of AllowanceAllowedMN/=. | MN/=. | |
| Notice of Allowance Data Verification CompletedAllowedN/=. | N/=. | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Appeal Brief FiledAP.B | AP.B | |
| Request for Extension of Time - GrantedXT/G | XT/G | |
| Notice of Appeal FiledN/AP | N/AP | |
| Mail Final Rejection (PTOL - 326)Final rejectionMCTFR | MCTFR | |
| Final RejectionFinal rejectionCTFR | CTFR | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Date Forwarded to Examiner | – | |
| Date Forwarded to Examiner | – | |
| Disposal for a RCE / CPA / R129AbandonedABN9 | ABN9 | |
| Request for Continued Examination (RCE)RCEX | RCEX | |
| Workflow - Request for RCE - BeginBRCE | BRCE | |
| Mail Final Rejection (PTOL - 326)Final rejectionMCTFR | MCTFR | |
| Final RejectionFinal rejectionCTFR | CTFR | |
| IFW TSS Processing by Tech Center CompleteTSSCOMP | TSSCOMP | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Corrected filing receiptCFRPT | CFRPT | |
| Incoming Letter Pertaining to the DrawingsLTDR | LTDR | |
| Response after Non-Final ActionA... | A... | |
| Request for Extension of Time - GrantedXT/G | XT/G | |
| Workflow incoming amendment IFWWAMD | WAMD | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Information Disclosure Statement (IDS) Filed | – | |
| Information Disclosure Statement (IDS) Filed | – | |
| Reference capture on IDSRCAP | RCAP | |
| Information Disclosure Statement (IDS) Filed | – | |
| Information Disclosure Statement (IDS) Filed | – | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Information Disclosure Statement (IDS) Filed | – | |
| Information Disclosure Statement (IDS) Filed | – | |
| Information Disclosure Statement (IDS) Filed | – | |
| Information Disclosure Statement (IDS) Filed | – | |
| Reference capture on IDSRCAP | RCAP | |
| Application Dispatched from OIPEOIPE | OIPE | |
| Oath or Declaration Filed (Including Supplemental)C602 | C602 | |
| Application Is Now CompleteCOMP | COMP | |
| Notice Mailed--Application Incomplete--Filing Date AssignedINCD | INCD | |
| Correspondence Address ChangeC.AD | C.AD | |
| IFW Scan & PACR Auto Security Review | – | |
| Initial Exam Team nnIEXX | IEXX |
20 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| AssignmentAS | AS | |
| Lapsed due to failure to pay maintenance feeLapsedFP | FP | |
| Lapse for failure to pay maintenance feesLapsedPATENT EXPIRED FOR FAILURE TO PAY MAINTENANCE FEES (ORIGINAL EVENT CODE: EXP.); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYLAPS | LAPS | |
| Information on status: patent discontinuationPATENT EXPIRED DUE TO NONPAYMENT OF MAINTENANCE FEES UNDER 37 CFR 1.362STCH | STCH | |
| Fee payment procedureMAINTENANCE FEE REMINDER MAILED (ORIGINAL EVENT CODE: REM.)FEPP | FEPP | |
| AssignmentAS | AS | |
| Fee paymentFPAY | FPAY | |
| Fee paymentFPAY | FPAY | |
| Fee payment procedurePAT HOLDER NO LONGER CLAIMS SMALL ENTITY STATUS, ENTITY STATUS SET TO UNDISCOUNTED (ORIGINAL EVENT CODE: STOL); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYFEPP | FEPP | |
| Fee payment procedurePAYOR NUMBER ASSIGNED (ORIGINAL EVENT CODE: ASPN); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYFEPP | FEPP | |
| Certificate of correctionCC | CC | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS |
Numbers
- Publication
- 07124189
- Publication, DOCDB
- 7124189
- Publication, EPODOC
- US7124189
- Application
- 9767465
- Application, DOCDB
- 76746501
- Application, EPODOC
- US20010767465
Titles
- English
- Spontaneous virtual private network between portable device and enterprise network
Patent term adjustment
- A delay
- +769 daysthe office missed an examination deadline
- Applicant delay
- −62 days
- Net adjustment
- 707 days
Classification
- CPC, 7
- H04L63/0227
- H04L12/4679
- H04L63/0272
- H04L63/166
- H04W12/06
- H04W76/12
- Y10S379/901
- IPC, 8
- G06F15 16
- G06F15 00
- G06F13 00
- G06F15 173
- G09C1 00
- H04L12 46
- H04L12 56
- H04L29 06
- USPC, 6
- 709227000
- 379901000
- 709217000
- 709219000
- 709225000
- 709229000